DNS
Resolution, TTL behaviour, traffic steering and failover latency.
5 to work through
-
beginner Multiple choice
At 09:00 a team creates the DNS record for a new regional endpoint. It resolves from their laptops at once, but part of the fleet keeps getting NXDOMAIN until about 09:20 even though the record's TTL is 60 seconds. Why?
2 min answer -
intermediate Multiple choice
Why is DNS a poor primary mechanism for fast failover, and what should be used instead for a globally distributed service?
2 min answer -
intermediate
You use DNS with a 60-second TTL for regional failover. During a test, some traffic still hit the failed region 40 minutes later. Explain.
2 min answer -
advanced
A globally distributed API experiences a regional networking failure. How should DNS, health checks, traffic steering, connection draining, failover and consistency interact?
2 min answer -
advanced
Your DR plan assumes a 60-second DNS TTL gives 60-second failover. Traffic to the failed region continues for 20 minutes. Explain and design something better.
2 min answer
3 terms in this topic
DNS Resolution Chain
The sequence of lookups from browser cache through OS cache, recursive resolver, root, TLD and authoritative server that turns a name into an address.
conceptDNS TTL
The time a DNS record may be cached, and a value that resolvers, operating systems and applications honour inconsistently.
practiceDNS TTL Strategy
Choosing record lifetimes to balance failover speed against query volume, knowing that resolvers and clients do not reliably honour them.
Neighbouring topics
Networking
General material on the network path underneath an architecture.
TCP/IP
Handshakes, congestion control, head-of-line blocking and connection reuse.
HTTP/1.1, HTTP/2 & HTTP/3
Multiplexing, prioritisation and the transport each is built on.
TLS & Certificates
Encryption, integrity, authentication, termination points and expiry.
Layer 4 vs Layer 7
Connection-level versus request-level balancing, and what each unlocks.
Reverse Proxies
One place for TLS, routing, caching, compression and rate limiting.
Content Delivery Networks
Edge caching, origin offload, spike absorption and dynamic content.
Firewalls & Security Groups
Default-deny, stateful rules, and restricting egress as well as ingress.
NAT & Egress
Outbound-only connectivity, its per-gigabyte cost and its zone binding.
VPC Design
Address planning, peering and the ranges you can never resize.
Subnetting
Tiering, zone binding, and sizing for an address-hungry platform.
Routing & BGP
How traffic finds you, anycast, and route withdrawal as a failure mode.
Service Mesh Networking
Sidecar proxies supplying mTLS, retries and traffic policy.
WebSockets & Realtime
Persistent bidirectional connections and the capacity model they impose.
gRPC Transport
HTTP/2 multiplexing, binary encoding and streaming semantics.
API Gateways
The single entry point, and the business logic that must stay out of it.
Network Performance
Latency floors, bandwidth-delay product, and what no code change fixes.
Private Connectivity
Private endpoints, peering and dedicated links to managed services.
Network Troubleshooting
Flow logs, packet paths, and localising a problem to a hop.